Fortinet

Fortisiem

33 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.25%
  • Veröffentlicht 11.03.2025 14:54:29
  • Zuletzt bearbeitet 25.07.2025 14:25:49

An incorrect authorization vulnerability [CWE-863] in FortiSIEM 7.2 all versions, 7.1 all versions, 7.0 all versions, 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions, 6.3 all versions, 6.2 all versions, 6.1 all versions, 5.4 al...

  • EPSS 0.35%
  • Veröffentlicht 11.03.2025 14:54:28
  • Zuletzt bearbeitet 22.07.2025 21:21:00

An exposure of sensitive information to an unauthorized actor in Fortinet FortiSIEM version 6.7.0 through 6.7.4 and 6.6.0 through 6.6.3 and 6.5.0 through 6.5.1 and 6.4.0 through 6.4.2 and 6.3.0 through 6.3.3 and 6.2.0 through 6.2.1 and 6.1.0 through ...

  • EPSS 0.29%
  • Veröffentlicht 11.02.2025 17:15:21
  • Zuletzt bearbeitet 16.07.2025 14:54:28

Multiple Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilities [CWE-79] in FortiSIEM 7.1 all versions, 7.0 all versions, 6.7 all versions incident page may allow an authenticated attacker to perform a c...

  • EPSS 0.5%
  • Veröffentlicht 14.01.2025 14:15:34
  • Zuletzt bearbeitet 03.02.2025 22:01:44

An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiSIEM ersion 7.1.7 and below, version 7.1.0, version 7.0.3 and below, version 6.7.9 and below, 6.7.8, version 6.6.5 and below, versi...

  • EPSS 0.59%
  • Veröffentlicht 14.01.2025 14:15:31
  • Zuletzt bearbeitet 16.07.2025 13:16:19

A allocation of resources without limits or throttling in Fortinet FortiSIEM 5.3 all versions, 5.4 all versions, 6.x all versions, 7.0 all versions, and 7.1.0 through 7.1.5 may allow an attacker to deny valid TLS traffic via consuming all allotted co...

  • EPSS 3.22%
  • Veröffentlicht 05.02.2024 14:15:59
  • Zuletzt bearbeitet 14.01.2026 14:16:10

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands via via crafted API requests.

  • EPSS 78.38%
  • Veröffentlicht 05.02.2024 14:15:57
  • Zuletzt bearbeitet 14.01.2026 14:16:10

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands via via crafted API requests.

  • EPSS 0.21%
  • Veröffentlicht 14.11.2023 18:15:55
  • Zuletzt bearbeitet 21.11.2024 08:27:00

An insertion of sensitive information into log file vulnerability [CWE-532] in FortiSIEM version 7.0.0, version 6.7.6 and below, version 6.6.3 and below, version 6.5.1 and below, version 6.4.2 and below, version 6.3.3 and below, version 6.2.1 and be...

  • EPSS 0.45%
  • Veröffentlicht 14.11.2023 18:15:52
  • Zuletzt bearbeitet 21.11.2024 08:21:28

An exposure of sensitive information to an unauthorized actor [CWE-200] in FortiSIEM version 7.0.0 and before 6.7.5 may allow an attacker with access to windows agent logs to obtain the windows agent password via searching through the logs.

  • EPSS 1.88%
  • Veröffentlicht 14.11.2023 18:15:48
  • Zuletzt bearbeitet 21.11.2024 08:09:55

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM version 5.4.0 and 5.3.0 through 5.3.3 and 5.2.5 through 5.2.8 and 5.2.1 through 5.2.2 and 5.1.0 through 5.1.3 and 5.0.0 through 5.0.1 a...